Skip to content

v0.1.3 - Serious scouting and authority hardening

Choose a tag to compare

@VrtxOmega VrtxOmega released this 11 Jul 14:37
b2bd5e4

PCF v0.1.3 adds impact-first serious candidate scouting and hardens the authority boundaries that keep automation advisory.

Highlights

  • Added broad, read-only serious candidate scouting with explicit collection-integrity and open-PR-overlap gates.
  • Expanded the adversarial residue corpus from 15 to 29 cases covering Unicode/control-text evasion, overlap ownership, repository-context vacuum, lane-gate omission, repro laundering, malformed MCP frames, and malformed batch inputs.
  • Made repository context, lane persistence, repro evidence, and MCP framing fail closed when evidence is missing or malformed.
  • Published through GitHub OIDC trusted publishing with npm provenance; no reusable npm token was required.

Verification

  • Tests: 242/242
  • Deterministic benchmark: 77/77
  • Adversarial red test: 29/29
  • Maintainer demo: PASS, replay stable, 0 regressions
  • MCP smoke: PASS
  • npm package dry run: PASS, 75 files
  • Clean registry install: PASS for pcf and pcf-mcp
  • Installed MCP surface: 25 tools, serious scout present, GitHub writes disabled

Main verification: https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156257898

Trusted publish: https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156361509

npm: https://www.npmjs.com/package/premature-contribution-firewall/v/0.1.3

Try It

npx -y -p premature-contribution-firewall@0.1.3 pcf --help
npx -y -p premature-contribution-firewall@0.1.3 pcf-mcp

PCF remains advisory. Heuristic results do not prove correctness, mergeability, authorship, or maintainer endorsement, and the MCP server exposes no public GitHub write tools.